GlassFish 3.1.1 security

From: Glenn Holmer <>
Date: Tue, 16 Aug 2011 16:50:42 -0500

We have an app that we've been running under GlassFish 3.0.1, and we
want to run it under 3.1.1. We've been running GlassFish fronted by
Apache, which handles SSL, and everything works OK. For 3.1.1, we used
these commands in place of the "old way" of putting the Tomcat jars in
GlassFish's lib/ directory:

asadmin create-http-listener --listenerport 8009 --listeneraddress --defaultvs server jk-listener
asadmin set

We are not yet using clustering/load balancing, so we are using the
default "server-config" configuration. Apache correctly forwards most
pages to GlassFish, except those that are protected.

In web.xml, we have this:

    <description>Phoenix security</description>
    <!-- the pages which will be protected: -->

This all worked fine under 3.0.1 (unless I forgot to write down a step
re. how we configured it).

But under 3.1.1, when I hit a page under /customers/, I get this:

[#|2011-08-16T16:38:07.075-0500|INFO|glassfish3.1.1||_ThreadID=22;_ThreadName=Thread-2;|JACC P
olicy Provider:Failed Permission Check: context (" phoenix-jee6/phoenix-jee6-war-bo_war ") , permission (" (
UserDataPermission /customers/checkout.html GET) ") |#]

;|PWC3989: An exception or error occurred in the container during the request processing
java.lang.ArrayIndexOutOfBoundsException: 1
        at org.apache.catalina.authenticator.AuthenticatorBase.invoke(

What have we done wrong? Is something different in 3.1.1, or did we just
miss a step?

